Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | vLLM trust_remote_codeÈÆ¹ýÔ¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2026-27893 |
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2026-3-27 |
Îó²îÆÀ·Ö | 8.8 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
vLLMÊÇÒ»¸ö¸ßÐÔÄܵĴóÄ£×ÓÍÆÀí¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬×¨Îª´ó¹æÄ£ÓïÑÔÄ£×ӵĸßÍÌÍÂÁ¿¡¢µÍÑÓ³Ù°²ÅŶøÉè¼Æ¡£¡£¡£¡£¡£¡£Æä½¹µãÌØÕ÷°üÀ¨PagedAttention¸ßЧÄÚ´æÖÎÀí¡¢²¢Ðл¯µ÷ÀíÓÅ»¯ÒÔ¼°¶Ô¶àGPU¡¢ÂþÑÜʽÇéÐεÄÓÅÒìÖ§³Ö¡£¡£¡£¡£¡£¡£vLLM¼æÈÝHugging Face½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬±ãÓÚÄ£×Ó¿ìËÙ¼ÓÔØÓ뼯³É£¬£¬£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚÍÆÀíЧÀÍ¡¢AIÓ¦Óúó¶ËÓëÉú²ú¼¶Ä£×Ó°²Åų¡¾°¡£¡£¡£¡£¡£¡£
2026Äê3ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬918²©ÌìÌÃÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½vLLM trust_remote_codeÈÆ¹ýÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚvllm/model_executor/models/nemotron_vl.pyºÍvllm/model_executor/models/kimi_k25.pyÎļþÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´úÂëÖÐÓ²±àÂëÉèÖÃtrust_remote_code=True£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÓû§ÏÔʽÉèÖÃtrust-remote-code=False±»Èƹý¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâHuggingFaceÄ£×Ó¿ÍÕ»£¬£¬£¬£¬£¬£¬£¬ÔÚÄ£×Ó¼ÓÔØÀú³ÌÖÐÖ´ÐÐí§ÒâPython´úÂ룬£¬£¬£¬£¬£¬£¬»ñȡЧÀÍÆ÷Ö´ÐÐȨÏÞ£¬£¬£¬£¬£¬£¬£¬½ø¶øÊµÏÖϵͳ¿ØÖÆ¡¢Êý¾ÝÇÔÈ¡»òºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¸ÃÎó²îÆÆËðÁËtrust_remote_codeÇå¾²»úÖÆµÄÐÅÈνçÏߣ¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¼°Ð§Àͱ»ÍêÈ«½ÓÊÜ£¬£¬£¬£¬£¬£¬£¬±£´æ½Ï¸ßºÏ¹æÎ£º¦¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
vLLM >=0.10.1
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/vllm-project/vllm/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/vllm-project/vllm/security/advisories/GHSA-7972-pg2x-xr59/